Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities affecting Langflow OSS, an open-source framework for building multimodal AI applications. It aggregates data related to Common Weakness Enumerations (CWE) and associated CVE identifiers that impact the software's integrity and confidentiality. The collection spans historical vulnerability reports, providing a comprehensive view of security issues identified within the Langflow ecosystem over time. Readers can use this resource to track advisories issued by the Langflow vendor and its maintainers, gaining insight into how specific threats are addressed. It also allows users to understand the nature of common weakness classes within the context of language model operations, such as injection flaws or improper access controls. Furthermore, one can look up a product's vulnerability history to assess past risk profiles and evaluate the effectiveness of remediation efforts. This aggregation serves as a reference for security researchers, developers, and operators who need to audit the current state of Langflow OSS. By examining the trends and types of vulnerabilities documented here, stakeholders can better prioritize patching strategies and enhance their deployment configurations. The data is organized to facilitate quick identification of critical issues and to support informed decision-making regarding software upgrades and security hardening measures.

Vendor: IBM

CVE IDTitleCVSSSeverityPublished
CVE-2026-13445 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-639 8.1 High2026-07-17
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-798 9.8 Critical2026-07-17
CVE-2026-13448 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints 8.1 High2026-07-17
CVE-2026-14499 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-78 8.8 High2026-07-17
CVE-2026-7667 Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing CWE-22 8.8 High2026-07-17
CVE-2026-7754 SSRF Protection Configuration Vulnerability 7.7 High2026-07-17
CVE-2026-7755 MCP Server Configuration Validator Bypass via File Upload API 8.8 High2026-07-17
CVE-2026-7872 Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass CWE-22 7.5 High2026-07-17
CVE-2026-8056 Parameter Injection Vulnerability in API Graph Execution Engine CWE-94 8.8 High2026-07-17
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability CWE-502 9.9 Critical2026-07-17
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint CWE-94 9.9 Critical2026-07-17
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution 9.8 Critical2026-07-17
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component CWE-94 9.9 Critical2026-07-17
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header CWE-22 9.9 Critical2026-07-17
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint CWE-306 9.8 Critical2026-07-17
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation CWE-94 9.9 Critical2026-07-17
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation CWE-94 9.8 Critical2026-07-17
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution CWE-306 9.8 Critical2026-07-17
CVE-2026-10129 SSRF via HTTP Redirect Following in Langflow API Request Component CWE-918 8.5 High2026-06-30
CVE-2026-10134 Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows CWE-94 10.0 Critical2026-06-30
CVE-2026-10140 Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem CWE-639 9.6 Critical2026-06-30
CVE-2026-10546 DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component CWE-918 7.1 High2026-06-30
CVE-2026-10560 Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS CWE-287 8.2 High2026-06-30
CVE-2026-10564 SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection CWE-918 8.2 High2026-06-30
CVE-2026-7663 Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass CWE-285 9.1 Critical2026-06-30
CVE-2026-7803 Flow Validation Bypass via Empty Component Type Field CWE-20 9.8 Critical2026-06-30
CVE-2026-7871 Insecure Deserialization in Redis Cache Backend CWE-502 9.8 Critical2026-06-30
CVE-2026-7873 Code Injection Vulnerability in Code Validation Endpoint CWE-94 9.9 Critical2026-06-30
CVE-2026-7874 Weak Cryptographic Key Derivation Exposed All Stored Credentials CWE-338 9.1 Critical2026-06-30
CVE-2026-7664 Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS CWE-287 9.8 Critical2026-06-22

All 35 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.